TAO endpoint hardening
Configure Windows agent uninstall, service-stop, and standard-user UI protections.
TAO endpoint hardening
Use Overview → Security Policies → TAO Agent to configure organization-wide Windows endpoint hardening. Enrolled agents receive changes through policy refresh after the next heartbeat.
Controls
- Require uninstall admin code blocks protected uninstall and reset workflows unless the approved code is supplied.
- Prevent stopping the Windows service protects the service from ordinary stop attempts while allowing clean operating-system shutdown.
- Restrict agent UI for standard users shows non-administrators a minimal Managed by Trustity screen. Local administrators retain the full status UI.
- Support contact (optional) displays an internal contact on the managed UI.
These controls apply to managed Windows endpoints. Confirm that the TAO Agent tab is visible and that the target devices are enrolled. Tabs depend on module entitlement; Vault users may not have access to the general hub.
Prepare the change
- Identify a pilot endpoint and maintenance window.
- Confirm the device is Online in Managed devices and note its current policy version.
- Assign separate custodians for the uninstall code and portal administration where required.
- Define a support contact that employees can recognize.
- Record the current checkbox states for rollback.
Configure endpoint hardening
- Open Security Policies and select TAO Agent.
- Select Require uninstall admin code if protected removal is required.
- Enter a strong value in Set uninstall code. If a code already exists, the field reads Enter new code to rotate…; leaving it blank preserves the configured code.
- Select Prevent stopping the Windows service to enable service-stop protection.
- Select Restrict agent UI for standard users to limit local UI disclosure and controls.
- Enter Support contact (optional), such as an IT helpdesk address.
- Select Save endpoint hardening.
- Wait for Endpoint hardening saved. Agents refresh on the next heartbeat.
- Refresh the page and confirm the selected controls remain enabled. A configured uninstall code is indicated without revealing it.
Validate on a pilot endpoint
- Wait for at least one new endpoint heartbeat.
- In Managed devices, confirm a recent Last heartbeat and an incremented policy version.
- Sign in as a standard user and verify the minimal Managed by Trustity UI when restriction is enabled.
- Confirm the configured Support contact appears.
- During the approved test window, verify that an ordinary service-stop attempt is denied when protection is enabled.
- Validate the protected uninstall workflow using the approved code only if your test plan requires it.
- Check Audit Logs for the TAO hardening update and investigate any tamper event generated by the controlled test.
- Expand rollout only after the pilot behaves as expected.
Rotate the uninstall code
- Generate a new strong code using your approved credential process.
- Enter it in Enter new code to rotate….
- Select Save endpoint hardening.
- Wait for pilot-device policy refresh and validate the new code.
- Update the controlled recovery record and retire the old value.
Do not disable protection merely because the code is unavailable. Use your approved recovery and Support process.
Troubleshooting
Failed to load endpoint hardening settings
Refresh once and verify the organization and entitlement. If the error persists, capture the time and visible error and open a support ticket.
Save fails
Confirm your session is active and the code meets your organization’s requirements. Retry without changing unrelated controls. Do not paste the code into a ticket.
Endpoint retains old behavior
Confirm the endpoint is online, has a new heartbeat, and reports a newer policy version. Restarting or reinstalling should not be the first response; diagnose connectivity and agent health first.
Standard users still see full details
Confirm Restrict agent UI for standard users is saved, the endpoint received the new policy, and the test account is not a local administrator.
Security notes
- Store the uninstall code in an approved privileged credential system; never share it in chat, email, screenshots, or tickets.
- Use a unique code for this purpose and rotate it after suspected exposure or administrator turnover.
- Keep Prevent stopping the Windows service enabled unless a documented operational requirement justifies otherwise.
- Ensure the support contact cannot be confused with an external or personal address.
